GPAC 软件中检测到存在安全漏洞(影响版本截至提交 f1219cde)。该漏洞位于组件 MP4Box 的文件 scenegraph/base_scenegraph.c 中的 函数。对受影响对象的特定操作会导致空指针引用(null pointer dereference)。此漏洞仅能从本地环境触发。该漏洞的利用方式已公开,并可能已被用于实际攻击。将软件升级至 abi-16.23 版本即可解决此问题。对应的补丁标识为 49dee5cad329cfed310c1682703df7daa47df31a。建议及时升级受影响
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90578 | 5.3 MEDIUM | GPAC MP4Box list.c gf_list_count use after free |
| CVE-2026-90577 | 5.3 MEDIUM | GPAC MP4Box base_scenegraph.c gf_node_get_field heap-based overflow |
| CVE-2026-90529 | 3.5 LOW | DataEase Symbolic Map symbolic-map.ts buildTooltip cross site scripting |
| CVE-2026-90573 | 3.3 LOW | GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference |
| CVE-2025-70819 | Zettlab D6 Ultra 1.7.0以下路径穿越挂载漏洞 |
No comments yet